AWS Misconfigurations
API Gateway Audit
Checks Performed
- ACM Certificate Expired
- ACM Certificates Should Have Minimum RSA Length
- AWS ACM Certificates Renewal Under 30 Days
- AWS ACM Certificates Renewal Under 45 Days
- AWS ACM Certificates Renewal Under 7 Days
- AWS ACM Certificates Not Valid
- AWS ACM Certificates With Wildcard Domain Names
- API Gateway X-Ray Should Be Enabled
- API Gateway V2 Should Have Authorization Type Configuration
- AWS ACM Certificates Not Valid
- API Gateway APIs Should Use SSL Certificates
- Cloudwatch Logs Must Be Enabled For All APIs
- Content Encoding Should Be Enabled For APIs
- Default Execution Endpoint Should Not Be Enabled
- Cloudwatch Metrics Must Be Enabled For All APIs
- Enable API Cache
- Enable Encryption For API Cache
- API Gateway Should Be Integrated With WAF
- Only Private End-Points Should Access APIs
- Expiring SSL Client Certificates Should Be Rotated
- API Gateway Execution Logging Should Be Enabled
- Active Tracing Should Be Enabled For API Gateway Stages
- EFS Encryption Enabled
- AWS KMS Customer Master Keys For EFS Encryption